The Ministry of Home Affairs has issued an advisory warning people against a growing cyber-fraud threat involving malicious Android applications disguised as pornography apps.
The National Cybercrime Threat Analytics Unit of the Ministry said such applications are being circulated mainly through advertisements on Facebook and Instagram, using names including Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa, along with similar variants.
Editorial Insight
Key Highlights
Important points readers should notice.
Hidden Threat: Fake entertainment apps are being used as a gateway to financial fraud.
Permission Trap: Accessibility access can give malicious apps powerful control over a device.
Social Media Route: Fraudsters are using targeted advertisements to reach potential victims.
Beyond Malware: Some apps can install additional packages and manipulate device settings.
Simple Defence: Avoiding unofficial APKs and unknown permissions can significantly reduce the risk.
According to the advisory, users who click on these malicious advertisements may be redirected to websites containing pornographic content. They are then encouraged to download APK files from sources outside the Google Play Store.
Once installed, the malicious applications can request sensitive permissions, including Accessibility access. The Ministry warned that granting such permissions to unknown applications can allow attackers to gain extensive control over a device and potentially carry out financial fraud. The Ministry also cautioned that some of these applications can download additional packages by disguising them as app updates. They may also install a Virtual Private Network (VPN) capable of routing internet traffic through servers controlled by attackers.
In some cases, the malicious application may attempt to prevent users from uninstalling it through normal device settings, making removal more difficult.
Editorial Analysis
Why This Matters
The warning highlights how seemingly harmless app downloads can become a gateway to device takeover and financial fraud. Users who install applications outside trusted app stores may unknowingly give attackers access to sensitive information and device functions.
The Ministry has advised citizens to install applications only through the Google Play Store or other trusted app stores and avoid downloading APK files through advertisements, unfamiliar websites or suspicious links.
Users have also been advised not to grant Accessibility permission to unknown applications and to check their devices if they suspect that a malicious application has been installed. If a suspicious application cannot be removed or returns after the device is restarted, the Ministry has advised users to back up important data and consider performing a factory reset.
The advisory comes amid growing concerns over cybercriminals using deceptive applications and social-media advertising to obtain access to users' devices and financial information.







